Cyber Security – have you audited your business recently?

Contact Us - Cyber Security Audit

As well the financial audits you must undertake for your business, a cyber-security audit is of critical importance. Analysing what your business is doing with regards to IT security procedures and finding weaknesses within them can prevent huge disruptions in the long run and can be a big part in maintaining your peace of mind.

It’s worth noting that audits, while pinpointing areas in which you may need to spend more time of money, can also highlight areas in which you can cut back a little and contribute to maintaining cyber security processes within the business as a process. The steps outlined within your audits can also serve as a set of guidelines and reminders for employees with regards to cyber security in the organisation. By both reviewing and reminding the best practice of IT procedures, audits are a clear-cut way of protecting your business within a contained set of steps as well as continuing to emphasise cyber security practices as a frame of reference.

Employee-focused steps

Phishing

Phishing attacks are the most common form of cyber-attacks, and as such it is crucial that your business and its employees is well equipped to detect and avoid phishing emails.

One of the simplest ways of preventing scammers from reaching you… is preventing them from reaching you. What this means is removing information that may be on your website which can help scammers contact you – important figures, team members, and their emails. Essentially directing scammers towards the key figures in your business increases the likelihood of an attack, so moving to a generalised enquiry form can reduce that risk.

However, there are things that you can look out for in potentially risky emails and that your employees should be aware of.

–       Bad grammar and/or spelling

–       Unofficial email addresses, such as b78hb@gmail.com, for example. Even if an email comes up as “Known Person”, it’s worth clicking on this label to check the address that the email comes from.

–       Unprompted links or requests for further information. If you are asked to follow a link, often via hyperlink, make sure that you check where the link will take you by hovering over the link itself to gain a preview of the web address.

BYOD policies

BYOD, or ‘Bring Your Own Device’ policies can be useful in terms of reducing the amount of company owned hardware and allowing employees to be more flexible about where they can work. However, BYOD presents significant risks despite its apparent efficiency.

BYOD makes knowing where and how securely your data is being held much more difficult, and also increases the risk of hardware theft or loss. Further, it’s harder to have standardised control over the patching or security policies of personal devices which subsequently puts your organisational data at risk. Reviewing these policies, therefore, can be a simple way of reducing cyber vulnerabilities.

Set policies and cyber-security training

While it may be obvious, having visible and clear policies concerning your cyber security processes is a key factor in making your business more secure. Not only does this prevent cyber breaches, but having well-documented and accessible polices about cyber security and other procedures can also help in making sure that your business and its employees comply with current legislation, notably with regards to GDPR legislation, given that the UK government has announced plans for stronger action against businesses which breach GDPR rules as part of the Queen’s Speech to parliament in May 2022.

Business-focused steps

Firewall configuration

A business’s firewall is the first line of defence for the entire network, clearing out all initial threats and monitoring what comes in and out of your system. However, incorrectly configured firewalls are alarmingly common and leave your initial security perimeter wide open for cyber criminals to take advantage of.

Firewalls monitor everything that passes through your network, making them even more crucial in the hybrid working environment that is increasingly common post pandemic. Allowing staff to access files from home, they also monitor the increased risk that remote access can pose. Making sure that this defensive mechanism is in place and fully functioning is a crucial step in the auditing process and can protect your business from the disruption that a breach can cause.

Patch-updates

Firstly, what are patches? Much like their name suggests, patches are software and operating system updates which aim to address security issues within a certain product. These very common updates aim to bridge any vulnerabilities that may crop up, and it’s really important to update with these patches as soon as possible to mitigate any vulnerabilities on your system.

Enabling automatic updates wherever possible means that such updates can be installed on your systems as soon as they become available, minimising the amount of time that any cyber breaches can get through the gaps in your security. The 2022 government Cyber Security Breaches Survey revealed that only a shocking 37% of businesses and 23% of charities have a patching policy as well as at least one of the other five government “cyber essentials”, leaving well over half of UK businesses vulnerable to attack.

Preventative policy

Services like Microsoft Azure enable business owners to standardise local device settings across an entire organisation, meaning that you can prevent specific file types from being run or prevent the use of ransomware and viruses before they become a threat. Having a standardised preventative policy can create some peace of mind for business owners and prevent some of the avenues that cyber criminals can use to attack your organisation.

Backups

To highlight how important having copies of your data can be, it’s worth being aware of the fact that 96% of US businesses don’t back up their data – despite the fact that 60% of businesses which experience a data loss incident shut down within six months. Backups prevent the significant risk to your business, so make sure that you have sufficiently encrypted in-house copies as well as offsite backups could be a lifeline should you experience a security breach or data loss incident.

Hardware

As well as managing your software, an awareness of the status of your hardware is just as important. Audits provide the opportunity to take stock of the age and status of your hardware and allow you to judge which pieces (if any) could need replacing.

Cloud and Mobile

Due to the hybrid working model that the majority of businesses have adopted in the wake of the pandemic, it’s more important than ever to consider cloud and mobile access in your audit. Some important considerations include:

–       Having clear and readily available guidelines about cloud storage and its associated risks

–       Having MFA (multi factor authentication) procedures in place across the business

–       Having steps in place when devices are stolen or lost.

 

If you’d like to find out more about digital audits and discuss with one of our team how you could benefit, then you can contact us here. And if you’re still not sure? Why not read more advice, tips, and tricks on the Corona IT blog.